US10999065B2 - Method and apparatus for updating a key in an active state - Google Patents
Method and apparatus for updating a key in an active state Download PDFInfo
- Publication number
- US10999065B2 US10999065B2 US15/999,503 US201815999503A US10999065B2 US 10999065 B2 US10999065 B2 US 10999065B2 US 201815999503 A US201815999503 A US 201815999503A US 10999065 B2 US10999065 B2 US 10999065B2
- Authority
- US
- United States
- Prior art keywords
- key
- access network
- network node
- air
- user equipment
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 98
- 230000004913 activation Effects 0.000 claims abstract description 36
- 230000000977 initiatory effect Effects 0.000 claims abstract description 14
- 230000004048 modification Effects 0.000 claims description 22
- 238000012986 modification Methods 0.000 claims description 22
- 230000004044 response Effects 0.000 description 9
- 230000011664 signaling Effects 0.000 description 8
- 230000006870 function Effects 0.000 description 4
- 230000000737 periodic effect Effects 0.000 description 4
- 238000005516 engineering process Methods 0.000 description 3
- 230000003213 activating effect Effects 0.000 description 2
- 230000006872 improvement Effects 0.000 description 2
- 230000008901 benefit Effects 0.000 description 1
- 230000002860 competitive effect Effects 0.000 description 1
- 230000003247 decreasing effect Effects 0.000 description 1
- 230000007774 longterm Effects 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 230000035484 reaction time Effects 0.000 description 1
- 230000009466 transformation Effects 0.000 description 1
- 238000000844 transformation Methods 0.000 description 1
- 230000007704 transition Effects 0.000 description 1
- 230000001960 triggered effect Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
- H04L9/0841—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
- H04L9/0844—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/068—Network architectures or network communication protocols for network security for supporting key management in a packet data network using time-dependent keys, e.g. periodically changing keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0891—Revocation or update of secret information, e.g. encryption key update or rekeying
-
- H04W12/04031—
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0431—Key distribution or pre-distribution; Key agreement
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the present invention relates to communications field, and more specifically, to method and apparatus for updating a key in an active state.
- the work on evolved access technology is in progress within the 3GPP organization.
- packet technology employed in the 3GPP system requires further improvement.
- Some most important parts of such evolved technology include: decreased delay and reaction time, accelerated user data rate, enhanced system capacity and coverage, and reduced overall cost of the operators.
- the evolved network structure is also an important indicator for the backward compatibility of the existing network.
- the user security procedure in the evolved network is required to guarantee that a security mechanism is provided which at least has a same level as that of the current 2G and 3G system.
- the core network of the wireless evolved network mainly includes logic function entities such as a Mobility Management Entity (MME), a System Architecture Evolution Gateway (SAE Gateway), and so forth.
- MME Mobility Management Entity
- SAE Gateway System Architecture Evolution Gateway
- the MME is responsible for mobility management of control plane including managing the user context and mobility state, allocating temporary user identification, security function, etc.
- the SAE Gateway is responsible for paging downlink data in an idle state, managing and storing IP bearer context and routing information in the network, etc., serving as an anchor point for user plane between different access systems.
- the security of the user plane is terminated at the access network, where a Base Station (BS) of the access network is referred to as an evolved NodeB (eNB).
- BS Base Station
- eNB evolved NodeB
- the security of the signaling plane is divided into two parts, namely Access Stratum signaling Radio Resource Control (RRC) and Non Access Stratum (NAS) signaling, terminated at the access network and the core network respectively.
- RRC Radio Resource Control
- NAS Non Access Stratum
- the key required to secure the signaling and the data is derived diversely from keys, i.e., CK, IK, generated during an Authentication and Key Agreement (AKA) procedure.
- AKA Authentication and Key Agreement
- K eNB-RRC-INI is a security key for the integrity of RRC signaling
- K eNB-RRC-ENC is a security key for the encryption of RRC signaling
- K eNB-RRC-UP is a security key for the encryption of user plane data
- K NAS-ENC is a security key for the encryption of the NAS
- K NAS-INI is a security key for the integrity of NAS signaling.
- a method and an apparatus for updating a key in an active state are provided according to embodiments of the present invention, in order to update the key in the active state.
- a method for updating a key in an active state includes following steps:
- a user equipment for updating a key in an active state is also provided according to an embodiment of the present invention.
- the user equipment includes:
- a terminal key update detecting unit configured to determine based on a pre-defined condition whether a key update needs to be initiated
- a terminal key update initiating unit configured to send a key update request message to a network side when the terminal key update detecting unit determines that the key needs to be updated.
- a network side entity for updating a key in an active state is also provided according to an embodiment of the present invention.
- the network side entity includes:
- a key update detecting unit configured to determine based on a pre-defined condition whether a key update needs to be initiated
- a key update initiating unit configured to send a request message for indicating the key update, when the key update detecting unit determines that the key needs to be updated
- a key updating unit configured to update the key when the user equipment or the network side entity initiates the key update.
- Another method for updating a key in an active state is also provided according to an embodiment of the present invention.
- FIG. 1 illustrates a schematic of a wireless evolved network according to the conventional art
- FIG. 2 illustrates a schematic of deriving relations regarding keys according to the conventional art
- FIG. 3 illustrates a flowchart of a method for updating a key in an active state according to a first embodiment of the present invention
- FIG. 4 illustrates a flowchart of updating a key in an active state which is actively initiated by a UE according to a second embodiment of the present invention
- FIG. 5 illustrates a flowchart of updating a key in an active state which is actively initiated by an eNB at a network side according to a third embodiment of the present invention
- FIG. 6 illustrates a flowchart of updating a key in an active state which is actively initiated by an eNB at a network side according to a fifth embodiment of the present invention
- FIG. 7 illustrates a flowchart of updating a key in an active state which is actively initiated by an MME at a network side according to a sixth embodiment of the present invention
- FIG. 8 illustrates a flowchart in which an eNB informs a UE of new keys via an air-interface key update procedure according to a seventh embodiment of the present invention
- FIG. 9 illustrates a flowchart in which an eNB informs a UE of new keys via an air-interface key update procedure according to an eighth embodiment of the present invention.
- FIG. 10 illustrates a schematic of a system for updating a key in an active state according to a ninth embodiment of the present invention.
- SAE System Architecture Evolution
- LTE Long Term Evolution
- the network side may determine whether a certain kind of key needs to be updated.
- a method for updating a key in an active state is that a user equipment (UE) may determine whether the key needs to be updated in the active state.
- the method for updating the key in the active state is as shown in FIG. 3 .
- the method includes below steps.
- Step s 301 A user equipment in an active state or a network side may determine that a key update is required based on a pre-configuration, and initiate the key update.
- the pre-configuration may include: (1) the user equipment finds out that a COUNT to which the User Plane (UP) or the RRC related is arriving at an upper threshold; (2) the user equipment has performed a handover between two eNBs, a handover within one eNB, or an inter-system handover; (3) the user equipment or the network side finds out that K ASME has not been updated for a long period.
- UP User Plane
- RRC Radio Resource Control
- Step s 302 The network side performs the key update procedure.
- the key update includes: updating all of the keys through the AKA authentication procedure; or, only updating derived keys of K ASME rather than performing AKA to update K ASME .
- Step s 303 The user equipment and the network side may acquire the updated keys.
- Step s 304 After the new keys are acquired, the user equipment and the network side may negotiate an activation time of the new keys.
- a method for updating a key in an active state is as shown in FIG. 4 , where the UE may actively initiate the key update procedure in the active state.
- the method includes below steps.
- Step s 401 When in active state, the UE finds out that the key needs to be updated due to some reason, the UE may actively trigger the key update procedure to the MME at the network side.
- the possible reasons for updating the key may include: (1) the COUNTs to which the UP or the RRC related is arriving at the upper threshold; (2) the UE just has performed a handover to a new eNB; (3) K ASME has not been updated for a long period.
- the UE may trigger the key update procedure by sending to the MME, a TAU/RAU request, or a special attach request, or a special service request, or a key update request message.
- Update type in the TAU/RAU request may be set as a special value, indicating that the key needs to be updated.
- the special value may utilize a unified special value for different reasons, or may distinctively utilize different values regarding different reasons (a RRC/UP counter value overflows, or a handover has been performed, or lifetime of K ASME expires).
- the UE may not indicate, but employ several existing values (e.g., the values indicating the routing/location area changing).
- the Update type since a periodic location registration requires no key update, the Update type shall be distinguished from it. To distinguish from the periodic location/routing registration, it is better for the Update type to employ a value other than the value indicating the “Periodic updating” such as 000.
- Step s 402 After the MME receives the request that triggers the key update procedure (may be one of the requests mentioned at step 401 ), the MME may perform the related key update procedure according to the request type.
- the AKA authentication procedure may be initiated if K ASME needs to be updated, e.g., an inter-system handover has been performed from GSM/UMTS to SAE/LTE, or lifetime of K ASME expires.
- New derived keys may be calculated based on K ASME , if there is no need to update K ASME , and only its derived keys need to be updated, e.g., the key update is required when a handover has been performed within the LTE system, or as a RRC/UP counter value arrives at an upper threshold, in which case only K eNB , or together with K NAS-int and K NAS-enc may be updated.
- Step s 403 The AKA procedure is performed to update the keys if it is determined to update K ASME at step s 402 . This step is optional.
- Step s 404 Each key is updated according to the determination at step s 402 .
- the related key is calculated based on the existing K ASME key, if only the derived keys of K ASME needs to be updated.
- Step s 405 The MME sends the new keys to the eNB.
- Step s 406 The eNB and the UE negotiate the activation time of the new keys.
- the eNB may notify the activation time of the new keys using one of the following methods, or a method other than the following ones.
- the eNB may inform the UE of the activation time of the new keys via a simplified security mode command, and the UE may acknowledge the reception of the security mode command.
- the UE and the network side may activate the new key according to the activation time of the new keys. If the NAS keys need to be updated, step s 405 may further include initiating an NAS security mode command in order to negotiate the activation time of new NAS keys.
- the eNB may initiate an intra-cell handover command, requesting the UE to perform handover to a current serving cell of the eNB itself so that the UE may use the new keys.
- the eNB may add a KSI along with each data packet in order to indicate which key the UE could use for decryption.
- step s 801 in the seventh embodiment may also refer to the below description described in step s 901 in the eighth embodiment.
- Step s 407 The network side sends a response message to the user in order to complete all the procedures for key update.
- the activation time of the new NAS keys may also be carried in this response.
- a method for updating a key in an active state is as shown in FIG. 5 , where the eNB at the network side may actively initiate the key update procedure in the active state.
- the present embodiment refers to the key update procedure initiated by the eNB.
- the COUNTs related to the UP or RRC encryption/integrity security is about to arrive at an upper threshold (about to wrap around)
- the related key may probably need to be updated in order to prevent repeated key stream.
- the user plane security key i.e., Kup-enc or KeNB
- K ASME may also be updated.
- the key update procedure in the third embodiment is described as follows.
- Step s 501 When the eNB finds out the key needs to be updated according to the above security requirement, the eNB may send to the MME a key update request message, requesting the MME to generate a new K eNB . The MME may then derive a new K eNB from K ASME .
- the key update request message may probably be: (1) a request message specifically for requesting the MME to update the key by the eNB, where an MME response is required regarding this request message; (2) a notification type of message, notifying the MME that the key needs to be updated, where no MME response is required regarding this notification message.
- Step s 502 The MME may update the key, K eNB , accordingly.
- K eNB may be derived by the MME from the existing K ASME , or, may be calculated by the MME after K ASME is updated through the AKA procedure.
- Step s 503 The MME sends the new K eNB to the eNB.
- the MME may send the key to the eNB in the following manners:
- the MME may also need to send other parameters required for calculating K eNB to the eNB in the above manners.
- a variable parameter e.g., a counter, a random number
- this variable parameter may also need to be sent to the eNB and then sent to the UE via the eNB, so that the UE may calculate the new K eNB using the same parameter.
- the eNB may derive new K UP and K RRC based on this new K eNB .
- C-RNTI or a random number may be employed as an input parameter during the deriving procedure. If C-RNTI is employed, the original C-RNTI may probably be utilized, or a C-RNTI parameter may probably be newly generated for the UE.
- Step s 504 An air-interface new key initiating procedure, i.e., a method concerning how to negotiate an activation time of the new keys is provided.
- PDCP Packet Data Convergence Protocol
- KSI Packet Data Convergence Protocol
- the UE is forced to perform an active-idle-active state transition, or an intra-cell handover, one may also refer to the below description described in step s 801 and step s 802 in the seventh embodiment or step s 901 and step s 902 in the eighth embodiment.
- the eNB may probably need to send a response message of (security) context modification after the new key is activated.
- a method for updating a key in an active state is as shown in FIG. 5 , where the eNB at the network side may actively initiate the key update procedure in the active state.
- the present embodiment refers to the key update procedure initiated by the eNB.
- the COUNTs related the UP or RRC encryption/integrity security is about to arrive at an upper threshold (about to wrap around)
- the related key may probably need to be updated in order to prevent repeated key streams.
- the user plane security key i.e., K UP-enc or K eNB
- K UP-enc or K eNB may probably need to be updated.
- K ASME and K MME there is no need to update K ASME and K MME , only K up and K RRC need to be updated.
- K eNB is updated in the third embodiment whereas K eNB is not updated in the present embodiment.
- the key update procedure in the fourth embodiment is described as follows.
- the eNB may generate a random number or a new C-RNTI, and then generate a new RRC/UP key using K eNB and other parameters.
- the eNB may inform the UE of the new key parameters via the air-interface key update procedure.
- the air-interface key update procedure utilized herein may refer to the description of following embodiments.
- a method for updating a key in an active state is as shown in FIG. 6 , where the eNB at the network side may actively initiate the key update procedure in the active state.
- the method includes below steps.
- Step s 601 In a non-handover scenario, if the network side such as eNB desires to update the key, an intra-cell handover command is thus sent to the UE, i.e., requesting the UE to perform handover to the source cell (target cell is identical with source cell).
- Step s 602 The UE may access the eNB cell again upon the receipt of the handover command.
- step s 603 to step s 609 in the follow-up procedure may refer to step s 401 to step s 407 in the second embodiment, which is omitted herein for brevity.
- a method for updating a key in an active state is as shown in FIG. 7 , where the MME at the network side may actively initiate the key update procedure.
- the method includes below steps.
- Step s 701 When the MIME at the network side finds out that K ASME has been used for a long period or an inter-RAT handover has been performed to the UE and so forth, after which K ASME needs to be updated, the MME may then determine to actively initiate the AKA procedure. The network side needs to set a valid time for each K ASME so that a corresponding procedure can be triggered instantly when the valid time arrives at the upper threshold.
- Step s 702 The MME actively initiates a special paging message to the UE. This step is optional.
- a Paging cause of the special paging request may be NULL or a special value indicative of the key update.
- Step s 703 The UE sends a paging response to the network upon the receipt of the paging message.
- Steps s 702 and s 703 are optional.
- Step s 704 When the MME sends to the UE an authentication request message in order to initiate to perform the AKA, or upon the receipt of the paging response, similar to the receipt of the paging message according to the conventional art, the MME may thus determine to perform the AKA, and may initiate the AKA procedure to the UE.
- Step s 705 The MME generates each derived key.
- Step s 706 The MME sends K eNB to the eNB.
- K eNB may be sent specifically in the manner of carrying the K eNB in the NAS message and informing the UE of the activation time of the new NAS keys, which is optional.
- the MME may send the new key to the eNB in one of the following manners:
- the context modification message may employ a special S 1 initial context establishment message, or a newly defined S 1 interface signaling.
- the context modification message includes the new key.
- the security context modification message includes the new key.
- Step s 707 The eNB and the UE negotiate the activation time of the new keys.
- the activation time of the NAS keys may also be negotiated during this procedure.
- Step s 708 The user communicates with the network side using the new keys.
- the eNB needs to inform the UE of the start of the new keys via the air-interface key update procedure.
- the main purpose of the air-interface key update procedure is to: (1) send parameters relating to the derived keys to the UE, e.g., a new C-RNTI or a random number; (2) inform the UE of the activation time of the keys.
- the description is made by way of Security Mode Command (SMC) procedure as an example, where the eNB informs the UE of the start of the new keys via the air-interface key update procedure.
- SMC Security Mode Command
- Step s 801 The eNB determines based on triggering reasons that a special SMC message needs to be sent to the UE.
- the SMC message may include one or more of the following parameters: (1) parameters required for deriving the key such as a new C-RNTI, a random number, and so forth; (2) a downlink activation time of the NAS keys; (3) a downlink activation time of the RRC keys; (4) an uplink and a downlink activation time of the user plane keys; (5) other possible parameters, e.g., an activation time of new keys for determining uplink data packets (including data packets of the user plane and the control plane).
- the eNB may: (1) stop sending the downlink data, so that the downlink activation time may begin from a next data packet; (2) continue to send data packets, but the PDCP SN for activating using of new keys may be set a little larger so as to avoid a key activation error due to the rapid sending of the packets.
- a new command such as newly defined security context modification command/security re-configuration command may also be utilized to request the UE to switch the key in use according to parameters or a time carried in the command.
- Step s 802 The UE returns a corresponding message to the eNB upon the receipt of the related message.
- the UE may derive new keys based on the related parameters.
- an activation time of the uplink data packets may also be required.
- the UE may then return the related message to the eNB.
- a PDCP SN for initiating the new keys is carried in the related message.
- the UE may not stop sending the data packets, but calculate new keys and acquire activation time of the new keys, and then send the new activation time to the eNB.
- the activation time of the keys for the uplink data packets needs to be set a little backward if this method is adopted.
- Step s 803 The air-interfaces may communicate under the protection of the new keys.
- the description is made by way of an intra-cell handover procedure as an example, where the eNB informs the UE of a new key activation via the air-interface key update procedure. Referring to FIG. 9 , following steps are included.
- Step s 901 The eNB determines based on triggering reasons that an HO Command message needs to be sent to the UE.
- the HO Command message may be sent to the UE in order to tell the UE to perform handover to another Cell, so that the HO Command message may carry air recourses, C-RNTI, etc., assigned by the another Cell.
- the HO Command message is merely to tell the UE to activate the updated keys rather than to instruct the UE to perform handover to other Cells.
- the eNB will not deliver any data packet after the HO Command message is sent.
- Step s 902 After the HO Command message is received by the UE, the UE may: (1) determine based on the values of the reason that the present handover is merely for the key update, and therefore synchronizing with the new cell is not required; (2) stop sending the uplink data packets; (3) derive new keys; (4) determine an activation time of the uplink data packets; (5) send a message to the eNB, informing the eNB of the activation time of the uplink data packets.
- Step s 903 The UE and the eNB may communicate with each other under the protection of the new keys.
- the user equipment in the active state and the network side may actively initiate the key update procedure in different cases, thereby solving the problem concerning the key update for a session in the active state.
- the implementation procedure is simple and easy to accomplish.
- a system for updating a key in an active state is also disclosed.
- the system includes at least a user equipment 10 and a network side entity 20 , where the user equipment in the active state and the network side entity may initiate the key update and update the key when a pre-defined condition is met.
- the user equipment 10 further includes:
- a terminal key update detecting unit 11 configured to determine based on a pre-defined condition whether the key update needs to be initiated
- a terminal key update initiating unit 12 configured to send a key update request message to the network side entity 20 when the terminal key update detecting unit 11 determines that the key needs to be updated;
- a terminal key update setting unit 13 configured to pre-define the condition for initiating the key update and provide the condition to the terminal key update detecting unit 11 .
- the network side entity 20 specifically includes:
- a key update detecting unit 21 configured to determine based on a pre-defined condition whether the key update needs to be initiated
- a key update initiating unit 22 configured to send a request message to the user equipment 10 for instructing the key update, when the key update detecting unit 21 determines that the key needs to be updated;
- a key updating unit 23 configured to update the key when the user equipment 10 or the network side entity 20 initiates the key update
- a key update setting unit 24 configured to pre-define the condition for initiating the key update and provide the condition to the key update detecting unit 21 ;
- a key start negotiating unit 25 configured to negotiate an activation time of the new keys with the user equipment.
- the functions of the units mentioned above may be realized via the MME at the network side and the eNB.
- the user equipment in the active state and the network side may actively initiate the key update procedure in different cases, thereby solving the problem concerning the key update for a session in the active state.
- the implementation procedure is simple and easy to accomplish.
- the user equipment in the active state and the network side may actively initiate the key update procedure in different cases, thereby solving the problem concerning the key update for a session in the active state.
- the present invention may be implemented with hardware, and may also be implemented with software on a necessary hardware platform. Based on this understanding, solutions provided by the present invention may be embodied in a software product.
- the software product may be stored in a nonvolatile storage media (may be a CD-ROM, a USB flash disc, a mobile hard disc, etc.)
- the software product may include a set of instructions enabling a computer device (may be a personal computer, a server, or a network device, etc.) to perform methods according to various embodiments of the present invention.
- the foregoing embodiments take SAE/LTE system as an example.
- the eNB described in the foregoing embodiments refers to a Base Station (BS) of the SAE/LTE system. It is readily appreciated by those skilled in the art that the BS is not limited to the eNB. Any Base Station that realizes the similar function as the eNB stated above shall fall within the scope of protection of the present invention.
- BS Base Station
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- User Interface Of Digital Computer (AREA)
Abstract
Description
TABLE 1 | |||
0 | 0 | 0 | RA updating |
0 | 0 | 1 | combined RA/LA updating |
0 | 1 | 0 | combined RA/LA updating with IMSI attach |
0 | 1 | 1 | Periodic updating |
Claims (20)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US15/999,503 US10999065B2 (en) | 2007-09-28 | 2018-08-20 | Method and apparatus for updating a key in an active state |
Applications Claiming Priority (7)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200710151885.5 | 2007-09-28 | ||
CN2007101518855A CN101400059B (en) | 2007-09-28 | 2007-09-28 | Cipher key updating method and device under active state |
PCT/CN2008/072534 WO2009043294A1 (en) | 2007-09-28 | 2008-09-25 | The method and device for updating the key in the active state |
US12/748,798 US8300827B2 (en) | 2007-09-28 | 2010-03-29 | Method and apparatus for updating key in an active state |
US13/587,340 US9031240B2 (en) | 2007-09-28 | 2012-08-16 | Method and apparatus for updating a key in an active state |
US14/674,155 US10057769B2 (en) | 2007-09-28 | 2015-03-31 | Method and apparatus for updating a key in an active state |
US15/999,503 US10999065B2 (en) | 2007-09-28 | 2018-08-20 | Method and apparatus for updating a key in an active state |
Related Parent Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US14/674,155 Continuation US10057769B2 (en) | 2007-09-28 | 2015-03-31 | Method and apparatus for updating a key in an active state |
Publications (2)
Publication Number | Publication Date |
---|---|
US20190007832A1 US20190007832A1 (en) | 2019-01-03 |
US10999065B2 true US10999065B2 (en) | 2021-05-04 |
Family
ID=40518250
Family Applications (6)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US12/748,798 Active 2029-02-22 US8300827B2 (en) | 2007-09-28 | 2010-03-29 | Method and apparatus for updating key in an active state |
US12/977,617 Expired - Fee Related US8023658B2 (en) | 2007-09-28 | 2010-12-23 | Method and apparatus for updating a key in an active state |
US13/229,400 Active US8144877B2 (en) | 2007-09-28 | 2011-09-09 | Method and apparatus for updating a key in an active state |
US13/587,340 Active 2029-03-07 US9031240B2 (en) | 2007-09-28 | 2012-08-16 | Method and apparatus for updating a key in an active state |
US14/674,155 Active US10057769B2 (en) | 2007-09-28 | 2015-03-31 | Method and apparatus for updating a key in an active state |
US15/999,503 Active US10999065B2 (en) | 2007-09-28 | 2018-08-20 | Method and apparatus for updating a key in an active state |
Family Applications Before (5)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US12/748,798 Active 2029-02-22 US8300827B2 (en) | 2007-09-28 | 2010-03-29 | Method and apparatus for updating key in an active state |
US12/977,617 Expired - Fee Related US8023658B2 (en) | 2007-09-28 | 2010-12-23 | Method and apparatus for updating a key in an active state |
US13/229,400 Active US8144877B2 (en) | 2007-09-28 | 2011-09-09 | Method and apparatus for updating a key in an active state |
US13/587,340 Active 2029-03-07 US9031240B2 (en) | 2007-09-28 | 2012-08-16 | Method and apparatus for updating a key in an active state |
US14/674,155 Active US10057769B2 (en) | 2007-09-28 | 2015-03-31 | Method and apparatus for updating a key in an active state |
Country Status (6)
Country | Link |
---|---|
US (6) | US8300827B2 (en) |
EP (2) | EP2197147B1 (en) |
CN (1) | CN101400059B (en) |
PT (1) | PT2197147T (en) |
TR (1) | TR201906527T4 (en) |
WO (1) | WO2009043294A1 (en) |
Families Citing this family (75)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
ZA200903044B (en) | 2006-11-01 | 2010-07-28 | Ericsson Telefon Ab L M | Telecommunication systems and encryption of control messages in such systems |
CN101309500B (en) | 2007-05-15 | 2011-07-20 | 华为技术有限公司 | Security negotiation method and apparatus when switching between different wireless access technologies |
US8311512B2 (en) * | 2007-06-21 | 2012-11-13 | Qualcomm Incorporated | Security activation in wireless communications networks |
CN101400059B (en) | 2007-09-28 | 2010-12-08 | 华为技术有限公司 | Cipher key updating method and device under active state |
CN102625302B (en) * | 2008-06-23 | 2016-03-30 | 华为技术有限公司 | Cipher key derivative method, equipment and system |
CN101883346B (en) * | 2009-05-04 | 2015-05-20 | 中兴通讯股份有限公司 | Safe consultation method and device based on emergency call |
CN101583130B (en) * | 2009-06-18 | 2015-09-16 | 中兴通讯股份有限公司 | The generation method and apparatus of air interface key |
CN101668289B (en) * | 2009-09-16 | 2014-09-10 | 中兴通讯股份有限公司 | Method and system for updating air interface secret key in wireless communication system |
CN102025685B (en) | 2009-09-21 | 2013-09-11 | 华为技术有限公司 | Authentication processing method and device |
CN102638793B (en) * | 2009-09-21 | 2013-09-25 | 华为技术有限公司 | Methods and device for authentication processing |
KR101700448B1 (en) | 2009-10-27 | 2017-01-26 | 삼성전자주식회사 | Method and system for managing security in mobile communication system |
CN101742492B (en) * | 2009-12-11 | 2015-07-22 | 中兴通讯股份有限公司 | Key processing method and system |
CN101715188B (en) * | 2010-01-14 | 2015-11-25 | 中兴通讯股份有限公司 | A kind of update method of air interface key and system |
CN102264065A (en) * | 2010-05-27 | 2011-11-30 | 中兴通讯股份有限公司 | Method and system for synchronizing access stratum security algorithms |
WO2012032218A1 (en) * | 2010-09-09 | 2012-03-15 | Nokia Corporation | Methods and apparatuses for handling an unavailable key |
US8699713B1 (en) * | 2011-09-30 | 2014-04-15 | Emc Corporation | Key update with compromise detection |
US9021246B2 (en) * | 2011-10-28 | 2015-04-28 | GM Global Technology Operations LLC | Method to replace bootloader public key |
US9521644B2 (en) | 2012-01-31 | 2016-12-13 | Qualcomm Incorporated | Methods and apparatus for providing network-assisted end-to-end paging between LTE devices |
US8964990B1 (en) * | 2012-05-17 | 2015-02-24 | Amazon Technologies, Inc. | Automating key rotation in a distributed system |
US8908868B1 (en) | 2012-05-17 | 2014-12-09 | Amazon Technologies, Inc. | Key rotation with external workflows |
US9590959B2 (en) | 2013-02-12 | 2017-03-07 | Amazon Technologies, Inc. | Data security service |
US9286491B2 (en) | 2012-06-07 | 2016-03-15 | Amazon Technologies, Inc. | Virtual service provider zones |
US10075471B2 (en) | 2012-06-07 | 2018-09-11 | Amazon Technologies, Inc. | Data loss prevention techniques |
US10084818B1 (en) | 2012-06-07 | 2018-09-25 | Amazon Technologies, Inc. | Flexibly configurable data modification services |
CN102740289B (en) * | 2012-06-15 | 2015-12-02 | 电信科学技术研究院 | A kind of key updating method, Apparatus and system |
US20150229620A1 (en) * | 2012-09-13 | 2015-08-13 | Nec Corporation | Key management in machine type communication system |
EP2912867A1 (en) * | 2012-10-29 | 2015-09-02 | Nokia Solutions and Networks Oy | Methods, apparatuses and computer program products enabling to improve handover security in mobile communication networks |
GB2509937A (en) | 2013-01-17 | 2014-07-23 | Nec Corp | Providing security information to a mobile device in which user plane data and control plane signalling are communicated via different base stations |
US10467422B1 (en) | 2013-02-12 | 2019-11-05 | Amazon Technologies, Inc. | Automatic key rotation |
US10211977B1 (en) | 2013-02-12 | 2019-02-19 | Amazon Technologies, Inc. | Secure management of information using a security module |
US9608813B1 (en) | 2013-06-13 | 2017-03-28 | Amazon Technologies, Inc. | Key rotation techniques |
US9300464B1 (en) * | 2013-02-12 | 2016-03-29 | Amazon Technologies, Inc. | Probabilistic key rotation |
US9547771B2 (en) | 2013-02-12 | 2017-01-17 | Amazon Technologies, Inc. | Policy enforcement with associated data |
US9367697B1 (en) | 2013-02-12 | 2016-06-14 | Amazon Technologies, Inc. | Data security with a security module |
US10210341B2 (en) | 2013-02-12 | 2019-02-19 | Amazon Technologies, Inc. | Delayed data access |
US9705674B2 (en) | 2013-02-12 | 2017-07-11 | Amazon Technologies, Inc. | Federated key management |
CN103259792B (en) * | 2013-04-28 | 2016-08-31 | 汉柏科技有限公司 | The method determining cipher code renewal time |
EP2965554B1 (en) * | 2013-09-11 | 2019-07-24 | Samsung Electronics Co., Ltd. | Method and system to enable secure communication for inter-enb transmission |
CN104519487A (en) * | 2013-09-30 | 2015-04-15 | 中兴通讯股份有限公司 | Method and device for processing PDCP (packet data convergence protocol) count values |
CN105706474B (en) * | 2013-10-30 | 2019-12-13 | 日本电气株式会社 | Apparatus, system and method for secure direct communication in proximity-based services |
CN105850167B (en) | 2013-12-24 | 2019-07-23 | 日本电气株式会社 | Equipment, system and method used in SCE |
WO2015106387A1 (en) * | 2014-01-14 | 2015-07-23 | 华为技术有限公司 | Key verification method, base station, user device and core network element |
CN105103577B (en) * | 2014-01-28 | 2019-05-24 | 华为技术有限公司 | A kind of device and method of encryption data |
CN103888261B (en) * | 2014-03-24 | 2017-10-27 | 北京智谷睿拓技术服务有限公司 | Certificate update method and device |
US9397835B1 (en) | 2014-05-21 | 2016-07-19 | Amazon Technologies, Inc. | Web of trust management in a distributed system |
US9438421B1 (en) | 2014-06-27 | 2016-09-06 | Amazon Technologies, Inc. | Supporting a fixed transaction rate with a variably-backed logical cryptographic key |
US9866392B1 (en) | 2014-09-15 | 2018-01-09 | Amazon Technologies, Inc. | Distributed system web of trust provisioning |
US9622080B2 (en) * | 2014-10-21 | 2017-04-11 | Qualcomm Incorporated | Cell update message management |
US9693219B2 (en) | 2014-10-24 | 2017-06-27 | Ibasis, Inc. | User profile conversion to support roaming |
KR102213885B1 (en) * | 2014-11-28 | 2021-02-08 | 삼성전자주식회사 | Apparatus and method for controlling security mode in wireless communication system |
US10469477B2 (en) | 2015-03-31 | 2019-11-05 | Amazon Technologies, Inc. | Key export techniques |
CN106332073B (en) * | 2015-06-16 | 2019-06-21 | 北京信威通信技术股份有限公司 | A kind of cluster group root key update method |
CN106533659A (en) * | 2015-09-14 | 2017-03-22 | 北京中质信维科技有限公司 | Secret key updating method and system |
US9883385B2 (en) | 2015-09-15 | 2018-01-30 | Qualcomm Incorporated | Apparatus and method for mobility procedure involving mobility management entity relocation |
WO2017092813A1 (en) | 2015-12-03 | 2017-06-08 | Telefonaktiebolaget Lm Ericsson (Publ) | Multi-rat access stratum security |
JP6630990B2 (en) | 2015-12-03 | 2020-01-15 | テレフオンアクチーボラゲット エルエム エリクソン(パブル) | Lightweight RRC connection setup in multi-RAT network |
WO2017173561A1 (en) * | 2016-04-05 | 2017-10-12 | Nokia Solutions And Networks Oy | Optimized security key refresh procedure for 5g mc |
US11044089B2 (en) * | 2016-05-05 | 2021-06-22 | Telefonaktiebolaget Lm Ericsson (Publ) | Security context escrowing |
CN107371155B (en) * | 2016-05-13 | 2021-08-31 | 华为技术有限公司 | Communication security processing method, device and system |
WO2018002447A1 (en) * | 2016-07-01 | 2018-01-04 | Nokia Technologies Oy | Secure communications |
CN107800502B (en) * | 2016-08-31 | 2019-05-31 | 深圳市中兴微电子技术有限公司 | The method and device switched between encryption and decryption mode |
PT3574669T (en) | 2017-01-30 | 2021-10-26 | Ericsson Telefon Ab L M | Security context handling in 5g during connected mode |
US10785193B2 (en) | 2017-03-30 | 2020-09-22 | Seagate Technology Llc | Security key hopping |
JP6996824B2 (en) | 2017-05-04 | 2022-01-17 | ホアウェイ・テクノロジーズ・カンパニー・リミテッド | Key acquisition methods and devices, as well as communication systems |
CN110574334B (en) * | 2017-05-05 | 2023-07-11 | 诺基亚技术有限公司 | Providing security information |
US10542428B2 (en) | 2017-11-20 | 2020-01-21 | Telefonaktiebolaget Lm Ericsson (Publ) | Security context handling in 5G during handover |
US11038923B2 (en) * | 2018-02-16 | 2021-06-15 | Nokia Technologies Oy | Security management in communication systems with security-based architecture using application layer security |
CN112534849B (en) * | 2018-08-09 | 2023-08-01 | 中兴通讯股份有限公司 | Security key generation techniques |
EP3713226A1 (en) * | 2018-09-28 | 2020-09-23 | Axis AB | Content security for a video stream |
WO2021192059A1 (en) * | 2020-03-24 | 2021-09-30 | 株式会社Nttドコモ | Terminal and communication method |
EP3910873A1 (en) | 2020-05-15 | 2021-11-17 | Kamstrup A/S | Key-management for advanced metering infrastructure |
KR20220084601A (en) * | 2020-12-14 | 2022-06-21 | 삼성전자주식회사 | Method and apparatus for authentication of access stratum based on public key infrastructure in handover scenario of next generation wireless communication system |
CN115734219A (en) * | 2021-08-30 | 2023-03-03 | 华为技术有限公司 | Communication method, device and system |
US11677552B2 (en) * | 2021-09-09 | 2023-06-13 | Coinbase Il Rd Ltd. | Method for preventing misuse of a cryptographic key |
CN114339909B (en) * | 2021-11-02 | 2024-09-27 | 哲库科技(北京)有限公司 | Cell switching method, device and computer readable storage medium |
Citations (112)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5241598A (en) | 1991-05-22 | 1993-08-31 | Ericsson Ge Mobile Communications, Inc. | Rolling key resynchronization in cellular verification and validation system |
US5265164A (en) | 1991-10-31 | 1993-11-23 | International Business Machines Corporation | Cryptographic facility environment backup/restore and replication in a public key cryptosystem |
US5404404A (en) | 1993-07-01 | 1995-04-04 | Motorola, Inc. | Method for updating encryption key information in communication units |
US5551073A (en) * | 1993-02-25 | 1996-08-27 | Ericsson Inc. | Authentication key entry in cellular radio system |
US5661803A (en) | 1995-03-31 | 1997-08-26 | Pitney Bowes Inc. | Method of token verification in a key management system |
US5742682A (en) | 1995-03-31 | 1998-04-21 | Pitney Bowes Inc. | Method of manufacturing secure boxes in a key management system |
US5752190A (en) * | 1993-07-30 | 1998-05-12 | Hughes Electronics | Supervisory audio tone based carrier-to-interference measurement in a mobile cellular communication system |
US5761306A (en) | 1996-02-22 | 1998-06-02 | Visa International Service Association | Key replacement in a public key cryptosystem |
US5805705A (en) | 1996-01-29 | 1998-09-08 | International Business Machines Corporation | Synchronization of encryption/decryption keys in a data communication network |
US5812666A (en) | 1995-03-31 | 1998-09-22 | Pitney Bowes Inc. | Cryptographic key management and validation system |
US5862452A (en) | 1997-10-20 | 1999-01-19 | Motorola, Inc. | Method, access point device and peripheral devices for low complexity dynamic persistence mode for random access in a wireless communication system |
US5887251A (en) * | 1996-10-30 | 1999-03-23 | Ericsson Inc. | Authentication key management for mobile stations |
WO1999038288A1 (en) | 1998-01-27 | 1999-07-29 | Dsc Telecom, L.P. | Method for dynamically updating cellular-phone-unique-encryption keys |
US5966443A (en) * | 1996-04-30 | 1999-10-12 | Motorola, Inc. | Method for correcting subscriber-based secure call keys |
US5974325A (en) * | 1991-09-24 | 1999-10-26 | Motorola, Inc. | Cellular radio system using common radio backbone |
US20010041591A1 (en) | 1999-08-19 | 2001-11-15 | Christopher Paul Carroll | Wireless universal provisioning device |
US20020066011A1 (en) * | 2000-11-28 | 2002-05-30 | Nokia Corporation | System for ensuring encrypted communication after handover |
US20020154776A1 (en) * | 2001-02-16 | 2002-10-24 | Sowa Hans Christopher | Method and apparatus for providing authentication in a communication system |
US20020154781A1 (en) * | 2001-02-16 | 2002-10-24 | Sowa Hans Christopher | Method and apparatus for storing and distributing encryption keys |
US20020164029A1 (en) | 2001-05-07 | 2002-11-07 | Jiang Sam Shiaw-Shiang | Frame number identification and ciphering activation time synchronization for a wireless communications protocol |
US20030033522A1 (en) | 1997-12-10 | 2003-02-13 | Izzet M Bilgic | Authentication and security in wireless communication system |
US20030092445A1 (en) * | 2001-11-15 | 2003-05-15 | Nokia Corporation | Method and apparatus for providing immediate ciphering after an inter-system UTRAN-GSM handover |
US20030099362A1 (en) | 2001-11-27 | 2003-05-29 | Doug Rollins | Method and apparatus for WEP key management and propagation in a wireless system |
US20030109256A1 (en) * | 2001-12-07 | 2003-06-12 | Holcman Alejandro R. | Method and apparatus for effecting handoff between different cellular communications systems |
US20030108007A1 (en) * | 2001-12-07 | 2003-06-12 | Holcman Alejandro R. | Method and apparatus for effecting handoff between different cellular communications systems |
US20030133576A1 (en) | 2000-10-18 | 2003-07-17 | Frederic Grumiaux | Generation of a common encryption key |
US20030219129A1 (en) * | 2002-05-21 | 2003-11-27 | Robert Whelan | System and method for providing WLAN security through synchronized update and rotation of WEP keys |
US6671507B1 (en) * | 2000-06-16 | 2003-12-30 | Siemens Aktiengesellschaft | Authentication method for inter-system handover between at least two radio communications systems |
US6701435B1 (en) | 1998-08-20 | 2004-03-02 | International Business Machines Corporation | Cryptographic key generation system |
US20040071293A1 (en) | 2002-10-09 | 2004-04-15 | Masato Yamamichi | Encryption apparatus, decryption apparatus and encryption system |
US20040072563A1 (en) * | 2001-12-07 | 2004-04-15 | Holcman Alejandro R | Apparatus and method of using a ciphering key in a hybrid communications network |
US20040103202A1 (en) | 2001-12-12 | 2004-05-27 | Secretseal Inc. | System and method for providing distributed access control to secured items |
US20050047598A1 (en) | 2003-09-03 | 2005-03-03 | Kruegel Chris A. | Managing multiple cryptographic periods in a single cryptographic group |
US6876747B1 (en) * | 2000-09-29 | 2005-04-05 | Nokia Networks Oy | Method and system for security mobility between different cellular systems |
US20050113070A1 (en) | 2003-11-21 | 2005-05-26 | Nec Corporation | Mobile terminal authentication method capable of reducing authentication processing time and preventing fraudulent transmission/reception of data through spoofing |
CN1642073A (en) | 2004-01-17 | 2005-07-20 | 神州亿品科技(北京)有限公司 | Group key consultation and updating method for wireless LAN |
US20050177723A1 (en) | 2004-02-10 | 2005-08-11 | Industrial Technology Research Institute | SIM-based authentication method capable of supporting inter-AP fast handover |
US20050176431A1 (en) * | 2004-02-11 | 2005-08-11 | Telefonaktiebolaget L M Ericsson (Publ) | Method for handling key sets during handover |
US20050226423A1 (en) * | 2002-03-08 | 2005-10-13 | Yongmao Li | Method for distributes the encrypted key in wireless lan |
US20050226420A1 (en) | 2002-05-17 | 2005-10-13 | Jakke Makela | Method and system in a digital wireless data communication network for arranging data encryption and corresponding server |
US20060047601A1 (en) | 2004-08-25 | 2006-03-02 | General Instrument Corporation | Method and apparatus for providing channel key data |
CN1777094A (en) | 2004-11-15 | 2006-05-24 | 中兴通讯股份有限公司 | Key reconsul tation trigger method in general pilot system |
US20060140410A1 (en) | 2004-12-27 | 2006-06-29 | Kabushiki Kaisha Toshiba | Wireless communication device and wireless communication method |
US20060178167A1 (en) * | 1997-04-24 | 2006-08-10 | Ntt Mobile Communications Network, Inc. | Method and system for mobile communications |
CN1835633A (en) | 2005-09-02 | 2006-09-20 | 华为技术有限公司 | Updating protocal method of secret keys |
CN1878058A (en) | 2006-07-12 | 2006-12-13 | 中国移动通信集团公司 | Subscriber terminal cipher key update method used in broadcast service |
US20070003062A1 (en) * | 2005-06-30 | 2007-01-04 | Lucent Technologies, Inc. | Method for distributing security keys during hand-off in a wireless communication system |
EP1746797A1 (en) | 2005-07-18 | 2007-01-24 | Research In Motion Limited | Scheme for resolving authentication in a wireless packet data network after a key update |
CN1937489A (en) | 2006-09-23 | 2007-03-28 | 西安西电捷通无线网络通信有限公司 | Network key management and session key updating method |
JP2007104430A (en) | 2005-10-05 | 2007-04-19 | Matsushita Electric Ind Co Ltd | Encrypted data transmitting apparatus, encryption key updating method, electronic device, program and recording medium |
CN1953369A (en) | 2006-09-30 | 2007-04-25 | 中国移动通信集团公司 | A method, system and device to initiate and identify secret key update request |
US7225161B2 (en) | 2001-12-21 | 2007-05-29 | Schlumberger Omnes, Inc. | Method and system for initializing a key management system |
US20070147620A1 (en) | 2005-12-28 | 2007-06-28 | Heyun Zheng | Method for encryption key management for use in a wireless mesh network |
US7245724B1 (en) | 2002-03-08 | 2007-07-17 | Atheros Communications, Inc. | Rekey operation with multiplexing capability |
US20070206799A1 (en) | 2005-09-01 | 2007-09-06 | Qualcomm Incorporated | Efficient key hierarchy for delivery of multimedia content |
US20070223706A1 (en) | 2005-12-12 | 2007-09-27 | Alexander Gantman | Certify and split system and method for replacing cryptographic keys |
US20070248232A1 (en) | 2006-04-10 | 2007-10-25 | Honeywell International Inc. | Cryptographic key sharing method |
US20070249352A1 (en) * | 2006-03-31 | 2007-10-25 | Samsung Electronics Co., Ltd. | System and method for optimizing authentication procedure during inter access system handovers |
US20070265875A1 (en) | 2006-05-10 | 2007-11-15 | Innovative Sonic Limited | Method and apparatus for setting ciphering activation time in a wireless communications system |
US20070271458A1 (en) | 2006-05-22 | 2007-11-22 | Peter Bosch | Authenticating a tamper-resistant module in a base station router |
US20070277035A1 (en) | 2006-05-26 | 2007-11-29 | Sarvar Patel | Encryption method for secure packet transmission |
US20070297610A1 (en) | 2006-06-23 | 2007-12-27 | Microsoft Corporation | Data protection for a mobile device |
US20080002829A1 (en) | 2006-06-27 | 2008-01-03 | Nokia Corporation | Identifiers in a communication system |
US20080016248A1 (en) | 2006-07-14 | 2008-01-17 | George Tsirtsis | Method and apparatus for time synchronization of parameters |
US20080039086A1 (en) * | 2006-07-14 | 2008-02-14 | Gallagher Michael D | Generic Access to the Iu Interface |
US20080039096A1 (en) | 2006-03-28 | 2008-02-14 | Nokia Corporation | Apparatus, method and computer program product providing secure distributed HO signaling for 3.9G with secure U-plane location update from source eNB |
US20080043669A1 (en) * | 2006-07-14 | 2008-02-21 | Gallagher Michael D | Generic Access to the Iu Interface |
US20080080713A1 (en) * | 2004-03-05 | 2008-04-03 | Seok-Heon Cho | Method For Managing Traffic Encryption Key In Wireless Portable Internet System And Protocol Configuration Method Thereof, And Operation Method Of Traffic Encryption Key State Machine In Subscriber Station |
US20080089293A1 (en) | 2006-10-12 | 2008-04-17 | Telefonaktiebolaget Lm Ericsson (Publ) | Inter-system handoffs in multi-access environments |
US20080095362A1 (en) | 2006-10-18 | 2008-04-24 | Rolf Blom | Cryptographic key management in communication networks |
US20080098467A1 (en) | 2006-10-20 | 2008-04-24 | Interdigital Technology Corporation | METHOD AND APPARATUS FOR SELF CONFIGURATION OF LTE E-NODE Bs |
US20080101611A1 (en) | 2004-11-16 | 2008-05-01 | Fredrik Lindholm | Key Distribution in Systems for Selective Access to Information |
US20080123851A1 (en) | 2006-04-18 | 2008-05-29 | Interdigital Technology Corporation | Method and system for securing wireless communications |
US20080130902A1 (en) | 2006-04-10 | 2008-06-05 | Honeywell International Inc. | Secure wireless instrumentation network system |
US20080133921A1 (en) | 2006-11-30 | 2008-06-05 | Oki Electric Industry Co., Ltd. | Message authentication system and message authentication method |
US20080176572A1 (en) | 2006-12-28 | 2008-07-24 | Nokia Corporation | Method of handoff |
US20080184032A1 (en) * | 2006-10-20 | 2008-07-31 | Changhong Li | Generating keys for protection in next generation mobile networks |
US20080181411A1 (en) | 2007-01-26 | 2008-07-31 | Karl Norrman | Method and system for protecting signaling information |
US20080188200A1 (en) * | 2007-02-02 | 2008-08-07 | Nokia Corporation | Security key generation for wireless communications |
US20080207168A1 (en) * | 2007-02-23 | 2008-08-28 | Nokia Corporation | Fast update message authentication with key derivation in mobile IP systems |
US20080233947A1 (en) * | 2007-03-22 | 2008-09-25 | Christian Herrero-Veron | Mobility management (mm) and session management (sm) for sae/lte |
US20080267407A1 (en) | 2007-04-26 | 2008-10-30 | Qualcomm Incorporated | Method and Apparatus for New Key Derivation Upon Handoff in Wireless Networks |
US20080273704A1 (en) | 2005-12-01 | 2008-11-06 | Karl Norrman | Method and Apparatus for Delivering Keying Information |
US20080318546A1 (en) | 2007-06-21 | 2008-12-25 | Qualcomm Incorporated | Security activation in wireless communications networks |
US20090034736A1 (en) * | 2007-08-02 | 2009-02-05 | Motorola, Inc. | Wireless device authentication and security key management |
US20090061877A1 (en) * | 2006-07-14 | 2009-03-05 | Gallagher Michael D | Generic Access to the Iu Interface |
US20090073936A1 (en) | 2007-09-14 | 2009-03-19 | Motorola, Inc. | Method and apparatus for inter-technology handoff of a user equipment |
US20090100268A1 (en) | 2001-12-12 | 2009-04-16 | Guardian Data Storage, Llc | Methods and systems for providing access control to secured data |
US20090164788A1 (en) | 2006-04-19 | 2009-06-25 | Seok-Heon Cho | Efficient generation method of authorization key for mobile communication |
US20090209259A1 (en) | 2008-02-15 | 2009-08-20 | Alec Brusilovsky | System and method for performing handovers, or key management while performing handovers in a wireless communication system |
US20090235075A1 (en) * | 2005-06-10 | 2009-09-17 | Seok-Heon Cho | Method for managing group traffic encryption key in wireless portable internet system |
US20100002883A1 (en) | 2007-08-03 | 2010-01-07 | Interdigital Patent Holdings Inc. | Security procedure and apparatus for handover in a 3gpp long term evolution system |
US20100056156A1 (en) * | 2007-05-15 | 2010-03-04 | Huawei Technologies Co., Ltd. | Method and apparatus for negotiating security during handover between different radio access technologies |
US20100095123A1 (en) | 2007-08-31 | 2010-04-15 | Huawei Technologies Co., Ltd. | Method, system and device for negotiating security capability when terminal moves |
US20100111308A1 (en) * | 2007-03-21 | 2010-05-06 | Nokia Siemens Networks Gmbh & Co. Kg | Key handling in communication systems |
US20100113033A1 (en) | 2007-08-22 | 2010-05-06 | Huawei Technologies Co., Ltd. | Communication system, network handover processing method and apparatus |
US20100166184A1 (en) * | 2008-12-29 | 2010-07-01 | Chih-Hsiang Wu | Method of handling security configuration in wireless communications system and related communication device |
US20100173610A1 (en) | 2009-01-05 | 2010-07-08 | Qualcomm Incorporated | Access stratum security configuration for inter-cell handover |
US20100172500A1 (en) * | 2009-01-05 | 2010-07-08 | Chih-Hsiang Wu | Method of handling inter-system handover security in wireless communications system and related communication device |
US20100177897A1 (en) | 2006-11-01 | 2010-07-15 | Gunnar Mildh | Telecommunication systems and encryption of control messages in such systems |
US20100190500A1 (en) * | 2006-09-28 | 2010-07-29 | Samsung Electronics Co., Ltd. | System and method of providing user equipment initiated and assisted backward handover in heterogeneous wireless networks |
US20100246533A1 (en) * | 2006-08-18 | 2010-09-30 | Niklas Lundin | Intersystem Change Involving Mapping Between Different Types Of Radio Bearers |
US20100278161A1 (en) | 2007-02-23 | 2010-11-04 | Nokia Corporation | Self optimization of forbidden neighbor cell list |
US20100316223A1 (en) * | 2007-09-17 | 2010-12-16 | Telefonaktiebolaget L M Ericsson | Method and Arrangement in a Telecommunication System |
US7936880B2 (en) | 2008-06-23 | 2011-05-03 | Huawei Technologies Co., Ltd. | Method, apparatus and system for key derivation |
US8023658B2 (en) | 2007-09-28 | 2011-09-20 | Huawei Technologies Co., Ltd. | Method and apparatus for updating a key in an active state |
US8073428B2 (en) | 2006-09-22 | 2011-12-06 | Kineto Wireless, Inc. | Method and apparatus for securing communication between an access point and a network controller |
US8081759B2 (en) | 2004-09-15 | 2011-12-20 | Nokia Corporation | Apparatus, and an associated method, for facilitating fast transition in a network system |
US8150397B2 (en) | 2006-09-22 | 2012-04-03 | Kineto Wireless, Inc. | Method and apparatus for establishing transport channels for a femtocell |
US8494163B2 (en) | 2006-10-03 | 2013-07-23 | Alcatel Lucent | Encryption in a wireless telecommunications |
US8621582B2 (en) * | 2004-05-12 | 2013-12-31 | Telefonaktiebolaget Lm Ericsson (Publ) | Authentication system |
US8948393B2 (en) | 2006-04-28 | 2015-02-03 | Qualcomm Incorporated | Uninterrupted transmission during a change in ciphering configuration |
-
2007
- 2007-09-28 CN CN2007101518855A patent/CN101400059B/en active Active
-
2008
- 2008-09-25 TR TR2019/06527T patent/TR201906527T4/en unknown
- 2008-09-25 EP EP08801004.6A patent/EP2197147B1/en active Active
- 2008-09-25 PT PT08801004T patent/PT2197147T/en unknown
- 2008-09-25 WO PCT/CN2008/072534 patent/WO2009043294A1/en active Application Filing
- 2008-09-25 EP EP19162161.4A patent/EP3591891B1/en active Active
-
2010
- 2010-03-29 US US12/748,798 patent/US8300827B2/en active Active
- 2010-12-23 US US12/977,617 patent/US8023658B2/en not_active Expired - Fee Related
-
2011
- 2011-09-09 US US13/229,400 patent/US8144877B2/en active Active
-
2012
- 2012-08-16 US US13/587,340 patent/US9031240B2/en active Active
-
2015
- 2015-03-31 US US14/674,155 patent/US10057769B2/en active Active
-
2018
- 2018-08-20 US US15/999,503 patent/US10999065B2/en active Active
Patent Citations (128)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5241598A (en) | 1991-05-22 | 1993-08-31 | Ericsson Ge Mobile Communications, Inc. | Rolling key resynchronization in cellular verification and validation system |
US5974325A (en) * | 1991-09-24 | 1999-10-26 | Motorola, Inc. | Cellular radio system using common radio backbone |
US5265164A (en) | 1991-10-31 | 1993-11-23 | International Business Machines Corporation | Cryptographic facility environment backup/restore and replication in a public key cryptosystem |
US5551073A (en) * | 1993-02-25 | 1996-08-27 | Ericsson Inc. | Authentication key entry in cellular radio system |
US5404404A (en) | 1993-07-01 | 1995-04-04 | Motorola, Inc. | Method for updating encryption key information in communication units |
US5752190A (en) * | 1993-07-30 | 1998-05-12 | Hughes Electronics | Supervisory audio tone based carrier-to-interference measurement in a mobile cellular communication system |
US5812666A (en) | 1995-03-31 | 1998-09-22 | Pitney Bowes Inc. | Cryptographic key management and validation system |
US5661803A (en) | 1995-03-31 | 1997-08-26 | Pitney Bowes Inc. | Method of token verification in a key management system |
US5742682A (en) | 1995-03-31 | 1998-04-21 | Pitney Bowes Inc. | Method of manufacturing secure boxes in a key management system |
US5805705A (en) | 1996-01-29 | 1998-09-08 | International Business Machines Corporation | Synchronization of encryption/decryption keys in a data communication network |
US5761306A (en) | 1996-02-22 | 1998-06-02 | Visa International Service Association | Key replacement in a public key cryptosystem |
US5966443A (en) * | 1996-04-30 | 1999-10-12 | Motorola, Inc. | Method for correcting subscriber-based secure call keys |
US5887251A (en) * | 1996-10-30 | 1999-03-23 | Ericsson Inc. | Authentication key management for mobile stations |
US20060178167A1 (en) * | 1997-04-24 | 2006-08-10 | Ntt Mobile Communications Network, Inc. | Method and system for mobile communications |
US20070298804A1 (en) | 1997-04-24 | 2007-12-27 | Ntt Mobile Communications Network, Inc. | Method and system for mobile communications |
US5862452A (en) | 1997-10-20 | 1999-01-19 | Motorola, Inc. | Method, access point device and peripheral devices for low complexity dynamic persistence mode for random access in a wireless communication system |
US20030033522A1 (en) | 1997-12-10 | 2003-02-13 | Izzet M Bilgic | Authentication and security in wireless communication system |
US7322041B2 (en) | 1997-12-10 | 2008-01-22 | Intel Corporation | Authentication and security in wireless communication system |
WO1999038288A1 (en) | 1998-01-27 | 1999-07-29 | Dsc Telecom, L.P. | Method for dynamically updating cellular-phone-unique-encryption keys |
US5991405A (en) | 1998-01-27 | 1999-11-23 | Dsc Telecom, L.P. | Method for dynamically updating cellular phone unique encryption keys |
US6701435B1 (en) | 1998-08-20 | 2004-03-02 | International Business Machines Corporation | Cryptographic key generation system |
US20010041591A1 (en) | 1999-08-19 | 2001-11-15 | Christopher Paul Carroll | Wireless universal provisioning device |
US6671507B1 (en) * | 2000-06-16 | 2003-12-30 | Siemens Aktiengesellschaft | Authentication method for inter-system handover between at least two radio communications systems |
US6876747B1 (en) * | 2000-09-29 | 2005-04-05 | Nokia Networks Oy | Method and system for security mobility between different cellular systems |
US20030133576A1 (en) | 2000-10-18 | 2003-07-17 | Frederic Grumiaux | Generation of a common encryption key |
US20020066011A1 (en) * | 2000-11-28 | 2002-05-30 | Nokia Corporation | System for ensuring encrypted communication after handover |
US20020154776A1 (en) * | 2001-02-16 | 2002-10-24 | Sowa Hans Christopher | Method and apparatus for providing authentication in a communication system |
US20020154781A1 (en) * | 2001-02-16 | 2002-10-24 | Sowa Hans Christopher | Method and apparatus for storing and distributing encryption keys |
US7123719B2 (en) | 2001-02-16 | 2006-10-17 | Motorola, Inc. | Method and apparatus for providing authentication in a communication system |
US20080013737A1 (en) | 2001-02-16 | 2008-01-17 | Motorola, Inc. | Method and apparatus for storing and distributing encryption keys |
US20020164029A1 (en) | 2001-05-07 | 2002-11-07 | Jiang Sam Shiaw-Shiang | Frame number identification and ciphering activation time synchronization for a wireless communications protocol |
US20030092445A1 (en) * | 2001-11-15 | 2003-05-15 | Nokia Corporation | Method and apparatus for providing immediate ciphering after an inter-system UTRAN-GSM handover |
US20030099362A1 (en) | 2001-11-27 | 2003-05-29 | Doug Rollins | Method and apparatus for WEP key management and propagation in a wireless system |
US20030108007A1 (en) * | 2001-12-07 | 2003-06-12 | Holcman Alejandro R. | Method and apparatus for effecting handoff between different cellular communications systems |
US20040072563A1 (en) * | 2001-12-07 | 2004-04-15 | Holcman Alejandro R | Apparatus and method of using a ciphering key in a hybrid communications network |
US20030109256A1 (en) * | 2001-12-07 | 2003-06-12 | Holcman Alejandro R. | Method and apparatus for effecting handoff between different cellular communications systems |
US20040103202A1 (en) | 2001-12-12 | 2004-05-27 | Secretseal Inc. | System and method for providing distributed access control to secured items |
US20090100268A1 (en) | 2001-12-12 | 2009-04-16 | Guardian Data Storage, Llc | Methods and systems for providing access control to secured data |
US7225161B2 (en) | 2001-12-21 | 2007-05-29 | Schlumberger Omnes, Inc. | Method and system for initializing a key management system |
US20070253554A1 (en) | 2002-03-08 | 2007-11-01 | Atheros Communications, Inc. | Reykey Operation With Multiplexing Capability |
US20050226423A1 (en) * | 2002-03-08 | 2005-10-13 | Yongmao Li | Method for distributes the encrypted key in wireless lan |
US7245724B1 (en) | 2002-03-08 | 2007-07-17 | Atheros Communications, Inc. | Rekey operation with multiplexing capability |
US7526092B2 (en) | 2002-03-08 | 2009-04-28 | Atheros Communications, Inc. | Rekey operation with multiplexing capability |
US20050226420A1 (en) | 2002-05-17 | 2005-10-13 | Jakke Makela | Method and system in a digital wireless data communication network for arranging data encryption and corresponding server |
US20030219129A1 (en) * | 2002-05-21 | 2003-11-27 | Robert Whelan | System and method for providing WLAN security through synchronized update and rotation of WEP keys |
US20040071293A1 (en) | 2002-10-09 | 2004-04-15 | Masato Yamamichi | Encryption apparatus, decryption apparatus and encryption system |
US20050047598A1 (en) | 2003-09-03 | 2005-03-03 | Kruegel Chris A. | Managing multiple cryptographic periods in a single cryptographic group |
US20050113070A1 (en) | 2003-11-21 | 2005-05-26 | Nec Corporation | Mobile terminal authentication method capable of reducing authentication processing time and preventing fraudulent transmission/reception of data through spoofing |
CN1642073A (en) | 2004-01-17 | 2005-07-20 | 神州亿品科技(北京)有限公司 | Group key consultation and updating method for wireless LAN |
US20050177723A1 (en) | 2004-02-10 | 2005-08-11 | Industrial Technology Research Institute | SIM-based authentication method capable of supporting inter-AP fast handover |
US20050176431A1 (en) * | 2004-02-11 | 2005-08-11 | Telefonaktiebolaget L M Ericsson (Publ) | Method for handling key sets during handover |
US7907733B2 (en) | 2004-03-05 | 2011-03-15 | Electronics And Telecommunications Research Institute | Method for managing traffic encryption key in wireless portable internet system and protocol configuration method thereof, and operation method of traffic encryption key state machine in subscriber station |
US20080080713A1 (en) * | 2004-03-05 | 2008-04-03 | Seok-Heon Cho | Method For Managing Traffic Encryption Key In Wireless Portable Internet System And Protocol Configuration Method Thereof, And Operation Method Of Traffic Encryption Key State Machine In Subscriber Station |
US8621582B2 (en) * | 2004-05-12 | 2013-12-31 | Telefonaktiebolaget Lm Ericsson (Publ) | Authentication system |
US20060047601A1 (en) | 2004-08-25 | 2006-03-02 | General Instrument Corporation | Method and apparatus for providing channel key data |
US8081759B2 (en) | 2004-09-15 | 2011-12-20 | Nokia Corporation | Apparatus, and an associated method, for facilitating fast transition in a network system |
CN1777094A (en) | 2004-11-15 | 2006-05-24 | 中兴通讯股份有限公司 | Key reconsul tation trigger method in general pilot system |
US20080101611A1 (en) | 2004-11-16 | 2008-05-01 | Fredrik Lindholm | Key Distribution in Systems for Selective Access to Information |
US20060140410A1 (en) | 2004-12-27 | 2006-06-29 | Kabushiki Kaisha Toshiba | Wireless communication device and wireless communication method |
US20090235075A1 (en) * | 2005-06-10 | 2009-09-17 | Seok-Heon Cho | Method for managing group traffic encryption key in wireless portable internet system |
US20070003062A1 (en) * | 2005-06-30 | 2007-01-04 | Lucent Technologies, Inc. | Method for distributing security keys during hand-off in a wireless communication system |
EP1746797A1 (en) | 2005-07-18 | 2007-01-24 | Research In Motion Limited | Scheme for resolving authentication in a wireless packet data network after a key update |
US20070206799A1 (en) | 2005-09-01 | 2007-09-06 | Qualcomm Incorporated | Efficient key hierarchy for delivery of multimedia content |
CN1835633A (en) | 2005-09-02 | 2006-09-20 | 华为技术有限公司 | Updating protocal method of secret keys |
WO2007025484A1 (en) | 2005-09-02 | 2007-03-08 | Huawei Technologies Co., Ltd. | Updating negotiation method for authorization key and device thereof |
JP2007104430A (en) | 2005-10-05 | 2007-04-19 | Matsushita Electric Ind Co Ltd | Encrypted data transmitting apparatus, encryption key updating method, electronic device, program and recording medium |
US20080273704A1 (en) | 2005-12-01 | 2008-11-06 | Karl Norrman | Method and Apparatus for Delivering Keying Information |
US20070223706A1 (en) | 2005-12-12 | 2007-09-27 | Alexander Gantman | Certify and split system and method for replacing cryptographic keys |
US20070147620A1 (en) | 2005-12-28 | 2007-06-28 | Heyun Zheng | Method for encryption key management for use in a wireless mesh network |
US20080039096A1 (en) | 2006-03-28 | 2008-02-14 | Nokia Corporation | Apparatus, method and computer program product providing secure distributed HO signaling for 3.9G with secure U-plane location update from source eNB |
US20070249352A1 (en) * | 2006-03-31 | 2007-10-25 | Samsung Electronics Co., Ltd. | System and method for optimizing authentication procedure during inter access system handovers |
US20070248232A1 (en) | 2006-04-10 | 2007-10-25 | Honeywell International Inc. | Cryptographic key sharing method |
US20080130902A1 (en) | 2006-04-10 | 2008-06-05 | Honeywell International Inc. | Secure wireless instrumentation network system |
US20080123851A1 (en) | 2006-04-18 | 2008-05-29 | Interdigital Technology Corporation | Method and system for securing wireless communications |
US20090164788A1 (en) | 2006-04-19 | 2009-06-25 | Seok-Heon Cho | Efficient generation method of authorization key for mobile communication |
US8948393B2 (en) | 2006-04-28 | 2015-02-03 | Qualcomm Incorporated | Uninterrupted transmission during a change in ciphering configuration |
US20070265875A1 (en) | 2006-05-10 | 2007-11-15 | Innovative Sonic Limited | Method and apparatus for setting ciphering activation time in a wireless communications system |
US20070271458A1 (en) | 2006-05-22 | 2007-11-22 | Peter Bosch | Authenticating a tamper-resistant module in a base station router |
US20070277035A1 (en) | 2006-05-26 | 2007-11-29 | Sarvar Patel | Encryption method for secure packet transmission |
US20070297610A1 (en) | 2006-06-23 | 2007-12-27 | Microsoft Corporation | Data protection for a mobile device |
US20080002829A1 (en) | 2006-06-27 | 2008-01-03 | Nokia Corporation | Identifiers in a communication system |
CN1878058A (en) | 2006-07-12 | 2006-12-13 | 中国移动通信集团公司 | Subscriber terminal cipher key update method used in broadcast service |
US20080039086A1 (en) * | 2006-07-14 | 2008-02-14 | Gallagher Michael D | Generic Access to the Iu Interface |
US20080016248A1 (en) | 2006-07-14 | 2008-01-17 | George Tsirtsis | Method and apparatus for time synchronization of parameters |
US20080043669A1 (en) * | 2006-07-14 | 2008-02-21 | Gallagher Michael D | Generic Access to the Iu Interface |
US20090061877A1 (en) * | 2006-07-14 | 2009-03-05 | Gallagher Michael D | Generic Access to the Iu Interface |
US20100246533A1 (en) * | 2006-08-18 | 2010-09-30 | Niklas Lundin | Intersystem Change Involving Mapping Between Different Types Of Radio Bearers |
US8073428B2 (en) | 2006-09-22 | 2011-12-06 | Kineto Wireless, Inc. | Method and apparatus for securing communication between an access point and a network controller |
US8150397B2 (en) | 2006-09-22 | 2012-04-03 | Kineto Wireless, Inc. | Method and apparatus for establishing transport channels for a femtocell |
US20090300358A1 (en) | 2006-09-23 | 2009-12-03 | China Iwncomm Co. Ltd | Method for managing network key and updating session key |
CN1937489A (en) | 2006-09-23 | 2007-03-28 | 西安西电捷通无线网络通信有限公司 | Network key management and session key updating method |
US20100190500A1 (en) * | 2006-09-28 | 2010-07-29 | Samsung Electronics Co., Ltd. | System and method of providing user equipment initiated and assisted backward handover in heterogeneous wireless networks |
CN1953369A (en) | 2006-09-30 | 2007-04-25 | 中国移动通信集团公司 | A method, system and device to initiate and identify secret key update request |
US8494163B2 (en) | 2006-10-03 | 2013-07-23 | Alcatel Lucent | Encryption in a wireless telecommunications |
US20080089293A1 (en) | 2006-10-12 | 2008-04-17 | Telefonaktiebolaget Lm Ericsson (Publ) | Inter-system handoffs in multi-access environments |
US20080095362A1 (en) | 2006-10-18 | 2008-04-24 | Rolf Blom | Cryptographic key management in communication networks |
US20080184032A1 (en) * | 2006-10-20 | 2008-07-31 | Changhong Li | Generating keys for protection in next generation mobile networks |
US20080098467A1 (en) | 2006-10-20 | 2008-04-24 | Interdigital Technology Corporation | METHOD AND APPARATUS FOR SELF CONFIGURATION OF LTE E-NODE Bs |
US20100177897A1 (en) | 2006-11-01 | 2010-07-15 | Gunnar Mildh | Telecommunication systems and encryption of control messages in such systems |
US20080133921A1 (en) | 2006-11-30 | 2008-06-05 | Oki Electric Industry Co., Ltd. | Message authentication system and message authentication method |
US20080176572A1 (en) | 2006-12-28 | 2008-07-24 | Nokia Corporation | Method of handoff |
US20080181411A1 (en) | 2007-01-26 | 2008-07-31 | Karl Norrman | Method and system for protecting signaling information |
US20080188200A1 (en) * | 2007-02-02 | 2008-08-07 | Nokia Corporation | Security key generation for wireless communications |
US20080207168A1 (en) * | 2007-02-23 | 2008-08-28 | Nokia Corporation | Fast update message authentication with key derivation in mobile IP systems |
US20100278161A1 (en) | 2007-02-23 | 2010-11-04 | Nokia Corporation | Self optimization of forbidden neighbor cell list |
US20100111308A1 (en) * | 2007-03-21 | 2010-05-06 | Nokia Siemens Networks Gmbh & Co. Kg | Key handling in communication systems |
US20080233947A1 (en) * | 2007-03-22 | 2008-09-25 | Christian Herrero-Veron | Mobility management (mm) and session management (sm) for sae/lte |
US20170339558A1 (en) * | 2007-04-26 | 2017-11-23 | Qualcomm Incorporated | Method and apparatus for new key derivation upon handoff in wireless networks |
US20080267407A1 (en) | 2007-04-26 | 2008-10-30 | Qualcomm Incorporated | Method and Apparatus for New Key Derivation Upon Handoff in Wireless Networks |
US20100056156A1 (en) * | 2007-05-15 | 2010-03-04 | Huawei Technologies Co., Ltd. | Method and apparatus for negotiating security during handover between different radio access technologies |
US20170245182A1 (en) * | 2007-05-15 | 2017-08-24 | Huawei Technologies Co., Ltd. | Method and apparatus for negotiating security during handover between different radio access technologies |
US20080318546A1 (en) | 2007-06-21 | 2008-12-25 | Qualcomm Incorporated | Security activation in wireless communications networks |
US20090034736A1 (en) * | 2007-08-02 | 2009-02-05 | Motorola, Inc. | Wireless device authentication and security key management |
US20100002883A1 (en) | 2007-08-03 | 2010-01-07 | Interdigital Patent Holdings Inc. | Security procedure and apparatus for handover in a 3gpp long term evolution system |
US20100113033A1 (en) | 2007-08-22 | 2010-05-06 | Huawei Technologies Co., Ltd. | Communication system, network handover processing method and apparatus |
US20100095123A1 (en) | 2007-08-31 | 2010-04-15 | Huawei Technologies Co., Ltd. | Method, system and device for negotiating security capability when terminal moves |
US20090073936A1 (en) | 2007-09-14 | 2009-03-19 | Motorola, Inc. | Method and apparatus for inter-technology handoff of a user equipment |
US20100316223A1 (en) * | 2007-09-17 | 2010-12-16 | Telefonaktiebolaget L M Ericsson | Method and Arrangement in a Telecommunication System |
US8660270B2 (en) * | 2007-09-17 | 2014-02-25 | Telefonaktiebolaget L M Ericsson (Publ) | Method and arrangement in a telecommunication system |
US9615249B2 (en) * | 2007-09-17 | 2017-04-04 | Telefonaktiebolaget Lm Ericsson (Publ) | Method and arrangement in a telecommunication system |
US20170170954A1 (en) * | 2007-09-17 | 2017-06-15 | Telefonaktiebolaget Lm Ericsson (Publ) | Method and arrangement in a telecommunication system |
US8023658B2 (en) | 2007-09-28 | 2011-09-20 | Huawei Technologies Co., Ltd. | Method and apparatus for updating a key in an active state |
US20090209259A1 (en) | 2008-02-15 | 2009-08-20 | Alec Brusilovsky | System and method for performing handovers, or key management while performing handovers in a wireless communication system |
US7936880B2 (en) | 2008-06-23 | 2011-05-03 | Huawei Technologies Co., Ltd. | Method, apparatus and system for key derivation |
US8019083B2 (en) | 2008-06-23 | 2011-09-13 | Huawei Technologies Co., Ltd. | Method, apparatus and system for key derivation |
US20100166184A1 (en) * | 2008-12-29 | 2010-07-01 | Chih-Hsiang Wu | Method of handling security configuration in wireless communications system and related communication device |
US20100172500A1 (en) * | 2009-01-05 | 2010-07-08 | Chih-Hsiang Wu | Method of handling inter-system handover security in wireless communications system and related communication device |
US20100173610A1 (en) | 2009-01-05 | 2010-07-08 | Qualcomm Incorporated | Access stratum security configuration for inter-cell handover |
Non-Patent Citations (17)
Title |
---|
3GPP TR 33.821 V0.1.0,3rd Generation Partnership Project;Technical Specification Group Services and System Aspects;Rationale and track of security decisions in Long Term Evolved (LTE)/3GPP System Architecture Evolution (SAE)(Release 8),Feb. 2007,total 82 pages. |
3GPP TR 33.821 V0.4.0 (Jul. 2007)(S3-070625);3rd Generation Partnership Project;Technical Specification Group Services and System Aspects;Rationale and track of security decisions in Long Term Evolved (LTE) RAN / 3GPP System Architecture Evolution (SAE) (Release 8),total 88 pages. |
3GPP TS 36.410 V0.1.0 (May 2007);3rd Generation Partnership Project;Technical Specification Group Radio Access Network;Evolved Universal Terrestrial Access Network (E-UTRAN); S1 General Aspects and Principles (Release 8),total 15 pages. |
3GPP TS 36.413 V1.0.0,3rd Generation Partnership Project;Technical Specification Group Radio Access Network;Evolved Universal Terrestrial Access Network (E-UTRAN); S1 Application Protocol (S1AP)(Release 8),Sep. 2007,total 41 pages. |
3GPP TSG RAN WG2#59 R2-073609,"Reply LS on Key change in LTE active mode",SA3,(S3-070616, to RAN2). Reply LS (to R2-073002) on Key change in LTE active mode,Aug. 20-24, 2007,total 2 pages. |
3GPP TSG RAN WG3 Meeting #57bis R3-071942,"Key Update in LTE-ACTIVE state",Huawei,Oct. 8-11, 2007,total 6 pages. |
3GPP TSG RAN WG3 Security S3#50 S3-080056,"AS key change on the fly (after AKA)",Ericsson, Feb. 25-29, 2008,total 4 pages. |
3GPP TSG SA WG3 Security—SA3#46b S3-070240,"Key change during LTE_ACTIVE",Nokia, Siemens Networks, Mar. 28-29, 2007,total 5 pages. |
3GPP TSG SA WG3 Security—SA3#47 S3-070475,"LS on Key change in LTE active mode", May 22-25, 2007,total 3 pages. |
3GPP TSG-RAN WG2 Meeting #58bis R2-072591,"Alternatives for Key Change on the Fly",Nokia, Nokia Siemens Networks,Jun. 25-29, 2007,total 2 pages. |
3GPP TSG-RAN WG2 Meeting #58bis Tdoc R2-073002,"Reply LS on Key change in LTE active mode",Ericsson, Jun. 25-29, 2007,total 2 pages. |
3GPP TSG-WG3 Meeting #48 S3-070616,"Reply LS on Key change in LTE active mode",SA3,Jul. 10-13,total 2 pages. |
3GPP, 3GPP TR 33.821 V0.3.0 (May 2007), 3GPP, May 2007. * |
3GPP, 3GPP TSG SA WG3 Security—SA3#46b, Mar. 2007. * |
3GPP, 3GPP TSG SA WG3 Security—SA3#47, May 2007. * |
Ericsson, [Draft] Reply LS on Key change in LTE active mode. 3GPP TSG-RAN WG2 Meeting #58bis, Orlando, U.S.A., Jun. 25-29, 2007, R2-072917, 2 pages. |
Nokia Siemens Networks, Nokia,"Evaluation of key change on the fly solutions",3GPP TSG SA WG3 Security—SA3#47 S3-070354,Tallinn, Estonia, May 22-25, 2007,total 3 pages. |
Also Published As
Publication number | Publication date |
---|---|
US8144877B2 (en) | 2012-03-27 |
US20120307803A1 (en) | 2012-12-06 |
US20110080875A1 (en) | 2011-04-07 |
US20100202618A1 (en) | 2010-08-12 |
EP2197147A4 (en) | 2012-09-12 |
US20150208240A1 (en) | 2015-07-23 |
US8300827B2 (en) | 2012-10-30 |
WO2009043294A1 (en) | 2009-04-09 |
TR201906527T4 (en) | 2019-05-21 |
EP2197147A1 (en) | 2010-06-16 |
US8023658B2 (en) | 2011-09-20 |
US9031240B2 (en) | 2015-05-12 |
EP3591891B1 (en) | 2021-11-10 |
CN101400059B (en) | 2010-12-08 |
CN101400059A (en) | 2009-04-01 |
EP2197147B1 (en) | 2019-03-27 |
PT2197147T (en) | 2019-06-21 |
US10057769B2 (en) | 2018-08-21 |
EP3591891A1 (en) | 2020-01-08 |
US20190007832A1 (en) | 2019-01-03 |
US20110310849A1 (en) | 2011-12-22 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US10999065B2 (en) | Method and apparatus for updating a key in an active state | |
US11228905B2 (en) | Security implementation method, related apparatus, and system | |
US11653199B2 (en) | Multi-RAT access stratum security | |
CN108632815B (en) | Communication method and device | |
KR101737425B1 (en) | Mehthod and apparatus for managing security in a mobiel communication system supporting emergency call | |
US20170359719A1 (en) | Key generation method, device, and system | |
EP2897398B1 (en) | Key isolation method and device | |
US10045261B2 (en) | Methods, systems, and devices for handover in multi-cell integrated networks | |
US20120077461A1 (en) | Method and system for preauthenticating a mobile node | |
US20220345883A1 (en) | Security key updates in dual connectivity | |
EP3228108B1 (en) | Method, computer program and network node for ensuring security of service requests |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
STPP | Information on status: patent application and granting procedure in general |
Free format text: DOCKETED NEW CASE - READY FOR EXAMINATION |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: NON FINAL ACTION MAILED |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: RESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINER |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: FINAL REJECTION MAILED |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: ADVISORY ACTION MAILED |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: NOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONS |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: NOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONS |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: PUBLICATIONS -- ISSUE FEE PAYMENT RECEIVED |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: PUBLICATIONS -- ISSUE FEE PAYMENT VERIFIED |
|
STCF | Information on status: patent grant |
Free format text: PATENTED CASE |